SHARE
Facebook X Pinterest WhatsApp

Burp Scanner Features & Pricing

  See our complete list of top penetration testing tools. The Bottom Line PortSwigger Web Security’s Burp is a top-rated web vulnerability scanner used in many organizations and is found in most penetration testing toolkits, though its strength is more on the scanning side than on penetration. A free version is limited in functionality, so […]

Written By
thumbnail Drew Robb
Drew Robb
Sep 24, 2019
eSecurity Planet content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More

 

See our complete list of top penetration testing tools.

The Bottom Line

PortSwigger Web Security’s Burp is a top-rated web vulnerability scanner used in many organizations and is found in most penetration testing toolkits, though its strength is more on the scanning side than on penetration. A free version is limited in functionality, so those interested in the complete package for enterprise-wide scalability and automation should be prepared to pay well. Security professionals needing only a good automated vulnerability scanner for code testing can make do with the much cheaper Professional version.

For more on the Burp Suite, see Getting Started with the Burp Suite: A Pentesting Tutorial

Type of tool: Web vulnerability scanner

Key features: PortSwigger Web Security offers the Burp web vulnerability scanner in three flavors:

  • The Enterprise Edition comes with an automated Web vulnerability scanner, scheduling of scans, scalability across the enterprise, and CI integration as well as a series of manual tools.
  • The Professional version doesn’t have scheduling, enterprise scalability or CI integration.
  • The Community Edition consists of a series of manual tools and is aimed at researchers and hobbyists. The free version has essential manual tools for carrying out scanning. activities.

Burp bills itself as the world’s most widely used web vulnerability scanner. Major retailers, banks and governments use it to protect applications. It can check for SQL injection, cross-site scripting (XSS) and other vulnerabilities (including those listed in the OWASP top 10). In addition to scanning, it is also used for compliance and security audit purposes.

Burp is a Java-based web vulnerability scanner, enabling IT to scan applications to gain an enterprise-wide view of the most significant vulnerabilities. Drill-down capabilities allow for a closer look at individual applications, URLs and parameters to view issues in more detail. Web vulnerabilities are classified by type and severity.

Burp pioneered the use of out-of-band techniques (OAST) to supplement regular scanning. Burp Collaborator detects server-side vulnerabilities that may not be noticeable when only the application’s external behavior is viewed. Burp functions as an HTTP proxy server so all HTTP/S traffic from the browser passes through it.

“Burp is my go-to tool for testing web applications,” said the CEO of a security firm.

Differentiator: Automation of scanning and repetitive functions, enterprise scalability.

What it can’t do: It is a vulnerability scanner with some penetration tools that attack the exploits it uncovers.

Cost: The Enterprise Edition costs $3,999 per year. The Professional version costs $399, and there is also a free edition.

thumbnail Drew Robb

Originally from Scotland, Drew Robb has been a writer for more than 25 years. He lives in Florida and specializes in IT, engineering, and business. As well as eWeek and TechRepublic, he writes for a wide range of magazines including Gas Turbine World, SDxCentral, and HR Magazine. He is the author of Server Disk Management in a Windows Environment (Auerbach Publications).

Recommended for you...

The 6 Best Enterprise Password Managers You’ll Actually Trust
Matt Gonzales
Aug 27, 2025
5 Cloud Security Providers You Might Be Overlooking
Matt Gonzales
Aug 25, 2025
5 Enterprise VPN Solutions Every Business Should Know
Matt Gonzales
Aug 25, 2025
Meet the Cybersecurity Startups Beating Hackers at Their Own Game
Maine Basan
Aug 20, 2025
eSecurity Planet Logo

eSecurity Planet is a leading resource for IT professionals at large enterprises who are actively researching cybersecurity vendors and latest trends. eSecurity Planet focuses on providing instruction for how to approach common security challenges, as well as informational deep-dives about advanced cybersecurity topics.

Property of TechnologyAdvice. © 2025 TechnologyAdvice. All Rights Reserved

Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.